Spying on Scammers [video]
bbc.co.uk
bbc.co.uk
That sentence annoys the heck out of me. As in- somehow - his actions should be vilified, yet the scammers ON THE VIDEO are provided the benefit of "allegations" against them?
It's very clear to me that we have lost trust in our public institutions because they have failed us. It is trivial, given a lack of a certain moral compass, to set up an international call center scam like the one in this story. I receive at least 3-4 of these calls per day on my own phone - the scale is absolutely immense. And yet the person who successfully reveals the depravity of what these people do is the one who is the criminal? To that I say let the scammers try and sue him.
If the governments can't or don't have the will to solve the problem, I say let the people do it for them. Before you accuse me of advocating for vigilante justice, there is precedent for this sort of thing: the TCPA, passed by Congress in 1991, provides for a Private Right of Action against these telephone scammers - meaning that private individuals have the right to sue the scammers, rather than waiting for collective government action. However, this no longer works with the international scale of modern phone scams.
It's a classic tragedy of the commons. The cost of making phone calls over VoIP is basically zero at this point. I believe that the solution is simple: first, make the economics work against the scammers by making VoIP more expensive and use those funds to create an abuse reporting and enforcement mechanism; second, make the source of all phone calls completely transparent to end-users (or at least power-users). VoIP abuse must be taken seriously otherwise there will be no public telephone network left for the rest of us. It'll just be a bunch of bots calling each other and us- what a dystopia.
1- It’s factually correct, hacking & spying is illegal. It can land a hacker serious jail time, regardless of how morally good their intentions are, and regardless of how morally bad the people being hacked are.
2- You can interpret the disclaimer as a warning to other vigilante hackers wanting to do good. Think of it not as that Jim is being vilified, but it’s a message to you to be careful.
3- Think of it as a standard disclaimer, like you see on many products you buy. It could be a liability concern for the BBC to report on vigilante hacking against scammers if they were judged by the UK government to be glorifying and encouraging hacking.
Let the fact that they’re reporting on this story and showing the videos and shaming the scammers speak for itself and outweigh the annoying disclaimer.
This is at best an oversimplification.
> This is equivalent to ripping off a drug dealer, the dealer can’t exactly contact the police and ask for help
If you go about murdering drug dealers "they're part of a different legal framework!" isn't going to get you far in your defense trial. Murder remains illegal regardless. It remains illegal if you do so if the drug dealer lives in another country as well.
Now, prosecution may be difficult - lack of cooperation from those involved, sympathetic juries and competing polities adding extra political elements and hurdles, and ambiguity over which system should do the prosecution, etc. - but saying "illegal doesn't apply" is overstating things, especially if, say, the other party is ever a bit more sympathetic - perhaps an innocent person caught in the crossfire of someone's overly aggressive vigilante campaign.
This is why we have human rights.
Now, it is true that these hacking victims (the call center) can’t exactly call the police. I mean they can, but they’d just end up volunteering to go to prison (or whatever the reprimand is for their own crimes). Still, they do operate under the same legal framework as all the law abiding people in India.
If I get a spam call, my phone provider should be liable as if they had originated the call. If they got it from another provider, that provider should be liable to them, and so on and so forth. (This would be done by voluntary agreement; only the last mile should be a legal requirement)
All I would have to do is then to report my provider and get the fine. They would then have to chase down whoever connected it to them, and so on and so forth, until we reach Ivan's Shady VoIP Solutions Ltd., headquartered in the Cayman Islands. If they don't pay, no provider would want to peer with them.
Victim in Moscow receives call from caller in Utah. They complain to Russia Telecom, who complain to Sprint, who fine, or cut-off, Joe Bloggs in Salt Lake City?
What evidence would the victim in Moscow need to provide?
1. Pay the fine for letting their customers send spam calls to Russia.
2. Ignore it, and hope they don't get depeered by Rostelecom.
If they choose the first option, they are faced with two new choices:
1. Stop the buck there, do not contact Joe, eat the loss.
2. Contact Joe and tell him to pay them $100 or get cut off.
This would lead to a self-regulatory process: bad actors would get depeered from the retail phone network, so scammers could only call other scammers.
EDIT: To clarify, Sprint wouldn't have any legal/criminal responsibilities here, everything beyond the last mile is purely voluntary, but they might have a contract with Rostelecom. If Sprint choose the second option, Rostelecom might be able to sue them in the Kansas courts for breach of contract.
Someone from Kansas rings someone in Russia. Rostelecom claim this breaks Russian law (say Rostelecom claims they discussed a gay pride event or whatever). Sprint and Rostelecom have a contract which means that Sprint have to pay $1 million because Rostelecom claim something bad has happened. Sprint cut off the PITA customer in the states as it's cheaper that way.
Why would Sprint sign that contract?
If they would not, you have no reason to peer with them. If their laws are too arduous to comply with, they would simply be disconnected from the phone network.
> Will I be bound by a local bylaw in oregon county misouri?
That depends on whether Oregon County, Missouri has the "cell carriers are liable for spam calls" rule. If it's just a federal law like the current ones, no.
You could even cross "charge more" and "authenticate senders" off the spam solutions bingo card.
(This seems to be less prevalent in the EU, but maybe that's my imagination? Or due to having only a mobile? We're certainly not free of tech support scammers)
What truce?
My spam box is as full as ever; the only difference is that automated spam filtering got better. And in the meantime, on-line advertising industry exploded, so I assume most of the would-be e-mail scammers are now promoting their stores and Kickstarter wares with ads on major social media platforms.
Unfortunately, you can't do automated spam filtering on phone calls, because the content isn't apparent until you pick up and start talking.
I believe the much smaller frequency of phone scams in the EU comes from countries here having actual regulation against cold-calling private individuals with business offers.
(Plus, the US and the UK are a much juicier target for these international scam calls, because everyone in the gullible population speaks English, unlike in the rest of the EU.)
I am in the EU and yes it is less prevalent because know your customer is more strictly enforced on telecoms and also newer infrastructure, smaller companies so capital costs for countermeasures are less. Mostly the stricter government regulation.